Apply now »

Application Security DevSecOps Specialist

Location: 

Brasov, RO Timisoara, RO Cluj, RO Remote, RO Iasi, RO Sibiu, RO Serbia remote, RS Novi Sad, RS Bucuresti, RO

Who we are

 

NTT DATA is one of the world's largest global security service providers, partnering with some of the most recognized security technology brands. We're looking for passionate, curious, and motivated individuals to join our team.


What you’ll be doing

 

  • Incorporate security controls and standards into all phases of the software development lifecycle (SDLC).
  • Collaborate with developers to adopt secure coding practices, including OWASP compliance.
  • Conduct threat modeling and evaluate design documents to identify security vulnerabilities.
  • Establish security requirements and acceptance criteria for application development projects.
  • Design and implement security automation within CI/CD workflows using tools for SAST, DAST, IAST, SCA and compliance monitoring.
  • Develop custom security testing frameworks compatible with agile and DevSecOps models.
  • Conduct infrastructure-as-code (IaC) configuration checks and enforce compliance policies.
  • Automate secrets scanning, credential hygiene practices, and dependency vulnerability reviews.
  • Execute static (SAST) and dynamic (DAST) application security assessments.
  • Perform manual penetration testing and secure code reviews to detect risks.
  • Analyze application dependencies and third-party components, ensuring vulnerability remediation.
  • Validate security fixes via rigorous regression testing and secure deployment methods.
  • Prepare training initiatives for developers on secure coding practices, application security principles, and DevSecOps workflows.
  • Create and disseminate security documentation, guidelines, and playbooks for developers and architects.
  • Mentor engineers to adopt security-first product development and incident prevention strategies.
  • Establish and support developer security champion programmes within agile teams.
  • Implement robust security controls for containerized workloads in Docker, Kubernetes, and similar platforms.
  • Design and secure API endpoints and microservices architectures.
  • Leverage cloud security services on AWS, Azure, or GCP to deliver secure, scalable solutions.
  • Advocate for best practices in secret management, repository vaulting, and cloud-native application monitoring.

 

What you'll bring along

 

  • Bachelor’s degree in Cybersecurity, Computer Science, Software Engineering, or equivalent experience.
  • Minimum 3-5 years of experience in application security engineering.
  • Familiarity with implementing container security policies and securing high-performance CI/CD development ecosystems.
  • Proficiency in multiple programming languages (e.g., Java, Python, JavaScript, Go, .NET).
  • Extensive experience deploying application security tools like SonarQube, Checkmarx, Veracode, OWASP ZAP.
  • Expertise in CI/CD tools and platforms (e.g., Jenkins, GitHub Actions, Azure DevOps).
  • Solid understanding of container orchestration technologies (e.g., Kubernetes, Docker).
  • Familiarity with cloud platforms (AWS, Azure, GCP) and IaC assessment tools (Terraform, CloudFormation).
  • Advanced knowledge of the OWASP Top 10 vulnerabilities, secure coding techniques, and cryptographic best practices.
  • Proficiency in API security testing and securing microservices.
  • Hands-on involvement in framework-based security compliance efforts (ISO 27001, GDPR, SOC 2).
  • Exceptional collaboration and communication abilities when interfacing with software teams.
  • Strong problem-solving mindset to balance security priorities in fast-paced DevOps environments.
  • Capable of delivering security-focused workshops and team mentoring.
  • Must meet UK SC Clearance eligibility guidelines.
  • Preferred certifications include CSSLP, GWEB, or a Certified DevSecOps Engineer qualification.
  • AWS / Azure / GCP Security specialization certifications are advantageous.
  • Excellent command of both spoken and written English.
Document

What’s in it for you


✔ New beginnings can be a challenge. We promise a smooth integration and a supportive mentor
✔ Pick your working style: choose from Remote, Hybrid or Office work opportunities
✔ Early bird or night owl? Our projects have different working hours to suit your needs
✔ Nobody is born an expert. Sharpen your tech skills with our sponsored certifications, trainings and top e-learning platforms
✔ We want you to stay healthy! Enjoy our Private Health Insurance ⁠– it’s custom-made for you
✔ A clear mind is a healthy mind. Attend individual coaching sessions or go one step further by joining our accredited Coaching School
✔ Make the most of our epic parties or themed events – they’re lovingly designed for our people and their families

✔ NTT DATA recruiters will never ask job seekers and candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties that may try to impersonate NTT DATA recruiters, either in writing or by phone, in an attempt to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will be associated with an @nttdata.com email address. NTT DATA will not use any non-NTT DATA or personal email domains (Gmail, Yahoo, etc.) or personal communication channels (WhatsApp, Facebook etc) at any time during the recruitment process. If you suspect any fraudulent activity, please contact us.


NTT DATA Romania is an equal opportunity employer and considers all applicants regardless to race, color, religion, citizenship, national origin, ancestry, age, sex, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic protected by law. We are committed to creating a diverse and inclusive environment for all employees.


Not the job for you? Perhaps you have a friend who would be a perfect fit. Send them this link!

What’s in it for you

  • New beginnings can be a challenge. We promise a smooth integration and a supportive mentor
  • Pick your working style: choose from Remote, Hybrid or Office work opportunities
  • Early bird or night owl? Our projects have different working hours to suit your needs
  • Nobody is born an expert. Sharpen your tech skills with our sponsored certifications, trainings and top e-learning platforms
  • We want you to stay healthy! Enjoy our Private Health Insurance ⁠– it’s custom-made for you
  • A clear mind is a healthy mind. Attend individual coaching sessions or go one step further by joining our accredited Coaching School
  • Make the most of our epic parties or themed events – they’re lovingly designed for our people and their families

 

Your unique talent is what matters. NTT DATA Romania is an equal opportunity employer and considers all applicants regardless to race, color, religion, citizenship, national origin, ethnicity, age, gender, sexual orientation, gender identity, genetic information, physical or mental disability, veteran or marital status, or any other characteristic.

 

Document

Third parties fraudulently posing as NTT DATA recruiters

NTT DATA recruiters will never ask job seekers and candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties that may try to impersonate NTT DATA recruiters, either in writing or by phone, in an attempt to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will be associated with an @nttdata.com email address. NTT DATA will not use any non-NTT DATA or personal email domains (Gmail, Yahoo, etc.) or personal communication channels (WhatsApp, Facebook etc) at any time during the recruitment process. If you suspect any fraudulent activity, please contact us.


#LI-AR2


Job Segment: Test Engineer, Testing, .NET, Computer Science, Cloud, Engineering, Technology

Apply now »